What is a security breach?
In the case of personal data, a data breach means that personal data is lost, stolen, misused or otherwise compromised without authorization or unintentionally.
Typical examples are
Security breaches can have serious consequences – for the individuals affected and for the company.
Do you need support?
Do I have to report an injury?
Notification to the FDPIC
Yes, data breaches must be reported under certain conditions:
Notification to the FDPIC is only mandatory in the case of high risks (due to the violation) for affected persons. This is not a clear concept and there are no binding examples in Switzerland.
If a notification is mandatory, it must as quickly as possible take place. There is no fixed duration, and certain clarifications may be made. In case of doubt, however, you should report more quickly and then report later if necessary.
Notification form FDPIC
The FDPIC provides a form for reporting to him. However, the form asks for too much information and the FDPIC is subject to the principle of publicity. Reports can therefore become public. A report by e‑mail is often more sensible.
Notification to affected persons
Data security breaches must be reported to the persons concerned if they need to take action to protect themselves (e.g. change a password, block an account, renew a passport). This may be the case even if no report has to be made to the FDPIC.
What do critical infrastructures have to report?
The Federal Act on Information Security at the Confederation (ISG) will be supplemented by provisions on the reporting obligation of operators of certain critical infrastructures. The revised provisions are entered into force on April 1, 2025.
Certain critical infrastructures (Kritis) must report cyber attacks:
Persons subject to registration are, for example, public authorities, social insurance institutions including pension funds, energy suppliers, banks, listed hospitals, medical laboratories, pharmaceutical manufacturers or distributors, registered FDA and certain providers in the SaaS, cloud and hardware sector and various other entities, provided that they have a Headquarters in Switzerland have.
The following must be reported At least partially successful cyberattacks. These are deliberate impairments of the confidentiality, availability or integrity of information or the traceability of its processing – the key term is “deliberate”: human error is not covered. Neither are port scans and the like.
However, cyberattacks only need to be reported if
The notification must be sent to the Federal Office for Cyber Security BACS.
Working materials on the ISG
We provide various materials on the ISG, including editions of the law with dispatch and explanatory report.
Are there any other reporting obligations?
In addition to the reporting obligations under the DPA, the GDPR and the GDPR, there may be further reporting obligations that are motivated by the specific objectives of the respective legal system. These include the following: